Many DeFi protocols are run by their governance and can be designed to let token holders propose and vote on changes. If an attacker seizes enough voting power, they can push through malicious smart contract changes to drain the treasury.
Flash loans make achieving that relatively cheap, allowing someone to borrow a fortune in governance tokens, vote, and repay it all in a single transaction. Protocols without a timelock or execution delay are the most exposed, with no window for anyone to notice and respond before the malicious proposal executes.
Who is exposed to risk from a governance takeover?
Depositors in any token-governed protocol, especially newer or thinly held systems where voting power is cheaper to accumulate, along with the protocols and curators whose products sit on top of them.







